User Authentication Security - Configure login security options to hinder password guessing attacks - maximum-time

Information

The Junos default behavior for login security provides reasonable protection from password guessing attacks, but may not be suitable for every environment.

Limit the maximum length of time in seconds available for a user to enter a username and password before the connection is terminated. The range is from 20 through 30 with a default of 120.

Solution

Configure login security for maximum amount of time a login attempt has before disconnect.

user@host# edit system login retry-options
user@host# set maximum-time 15

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7a.

Plugin: Juniper

Control ID: bb7cacc276fb7cc3483e3546e63c88b40c52a4fb3ff37ed73f8370bde80ae1a8